Access Control Policy
DU-1-POL-717-001 · owner: Operations · QMS clause: 07.01.07
Confidential Business Information (CBI) — do not distribute. This document contains proprietary information of DroneUp, LLC. It is intended solely for the information and use of parties operating on behalf of DroneUp, LLC and its affiliates. Such proprietary information may not be used, reproduced, or disclosed to any other parties for any other purpose without express written permission. The information contained in this document is effective as of the revision date in the document control record.
Revision history
| Version | Date | Description | Updated by |
| 1 | 2026-06-19 | Initial publication. Migrated from the former Access Management policy document and aligned to NIST 800-171 r3. | SM |
1. Purpose
This policy establishes DroneUp’s organization-level direction for controlling access to information systems, data, and facilities throughout the information lifecycle. It sets the management intent and enforceable expectations for how access is authorized, enforced, managed, reviewed, and revoked across DroneUp systems and operations, and delegates the implementing specifics to the subordinate standards and procedures named in this policy.
2. Scope
This Access Control Policy [DU-1-POL-717-001] operates under the authority of the Information Security Program Policy [DU-1-POL-521-001], which governs DroneUp’s Information Compliance Program.
This policy establishes DroneUp’s access control requirements and delegates their implementation to the following subordinate documents:
- Group-based Access Control Subpolicy [DU-2-SUB-717-001]
- Separation of Duties Subpolicy [DU-2-SUB-717-002]
- System Use Notification Subpolicy [DU-2-SUB-717-003]
- Connectivity and Mobility Subpolicy [DU-2-SUB-717-004]
- Mobile Device Management (MDM) Subpolicy [DU-2-SUB-717-005]
- Account Management Procedure [DU-2-PRO-717-001]
- Access Enforcement Procedure [DU-2-PRO-717-002]
- Information Flow Enforcement Procedure [DU-2-PRO-717-003]
- Least Privilege Procedure [DU-2-PRO-717-004]
- Least Privilege - Privileged Accounts Procedure [DU-2-PRO-717-005]
- Least Privilege - Privileged Functions Procedure [DU-2-PRO-717-006]
- Unsuccessful Logon Attempts Procedure [DU-2-PRO-717-007]
- System Use Notification Procedure [DU-2-PRO-717-008]
- Device Lock Procedure [DU-2-PRO-717-009]
- Session Termination Procedure [DU-2-PRO-717-010]
- Remote Access Procedure [DU-2-PRO-717-011]
- Wireless Access Procedure [DU-2-PRO-717-012]
- Access Control for Mobile Devices Procedure [DU-2-PRO-717-013]
- Use of External Systems Procedure [DU-2-PRO-717-014]
- Publicly Accessible Content Procedure [DU-2-PRO-717-015]
Who this applies to: all DroneUp employees, contractors, and consultants, and all dedicated external service providers who are granted access to DroneUp information systems, data, or facilities.
What this covers: all systems, data, and operations that create, receive, process, store, or transmit information on behalf of DroneUp, or information entrusted to DroneUp by clients, partners, suppliers, or the U.S. Government. This includes logical access to business and production systems, physical access to DroneUp facilities and designated spaces, remote access, wireless access, mobile device access, use of external systems and portable storage, and publicly accessible content.
Review and update this policy at least annually and upon Significant Change, in accordance with the document control record. Non-compliance may result in disciplinary action up to and including termination, as defined in Section 19. Direct questions to the Information Security team through designated support channels.
Compliance and control framework alignment
This policy is designed to address the Access Control control family (03.01) of NIST SP 800-171 Rev. 3. DroneUp has not completed a formal audit against this framework. The specific requirements addressed are recorded in the control mapping for this document rather than in the section headings.
3. Account Management
The Accountable Security Authority must:
- Establish how system accounts are governed across DroneUp, including which kinds of accounts are permitted and the conditions under which any account may exist, so that every account traces back to an approved, legitimate need, in accordance with the Account Management Procedure [DU-2-PRO-717-001].
Access Managers must:
- Maintain an accurate picture of who is entitled to the systems and facilities they own, and reconfirm on a recurring basis that each entitlement still matches a current business need, giving the closest scrutiny to elevated access, in accordance with the Account Management Procedure [DU-2-PRO-717-001].
Information Systems Personnel must:
- Ensure access exists only while a legitimate need remains, granting it on approval and withdrawing it without undue delay when an individual’s status, role, or need changes, and keeping the relevant managers informed of those changes, in accordance with the Account Management Procedure [DU-2-PRO-717-001] and the Personnel Termination and Transfer Procedure [DU-2-PRO-511-002].
- Keep account use under routine oversight so that dormant, unnecessary, or misused access is identified and addressed, in accordance with the Account Management Procedure [DU-2-PRO-717-001].
All Personnel must:
- Secure their sessions when stepping away and not leave systems open to others, in accordance with the Acceptable Use Policy [DU-1-POL-521-002].
4. Access Enforcement
Access Managers must:
- Base every access decision on the requester’s role and demonstrated business need rather than seniority or convenience, in accordance with the Access Enforcement Procedure [DU-2-PRO-717-002].
Information Systems Personnel must:
- Ensure that what any person or system can reach always reflects a current, approved authorization, and that connections between systems are sanctioned and recorded before they are enabled, in accordance with the Access Enforcement Procedure [DU-2-PRO-717-002].
All Personnel must:
- Safeguard their credentials and use their access only for the purposes it was granted, neither sharing access nor enabling it for others, in accordance with the Acceptable Use Policy [DU-1-POL-521-002].
5. Information Flow Enforcement
Data Owners must:
- Grant access to Controlled Unclassified Information and Confidential Business Information on the basis of a demonstrated need tied to a specific role, contract, or project, in accordance with the Information Flow Enforcement Procedure [DU-2-PRO-717-003].
Information Systems Personnel must:
- Ensure Controlled Unclassified Information moves only to the people, systems, and destinations approved to receive it, and is kept from crossing outside its authorized boundaries, in accordance with the Information Flow Enforcement Procedure [DU-2-PRO-717-003].
6. Separation of Duties
The Accountable Security Authority must:
- Ensure that responsibility for sensitive and high-risk activities is divided so that no single individual can carry such a process through from end to end alone, and keep the record of those divided responsibilities current, in accordance with the Separation of Duties Subpolicy [DU-2-SUB-717-002].
Access Managers and Information Systems Personnel must:
- Keep the request for access and the approval of access in different hands, and apply DroneUp’s defined division of duties when assigning access, in accordance with the Separation of Duties Subpolicy [DU-2-SUB-717-002].
7. Least Privilege
Access Managers and Information Systems Personnel must:
- Grant each individual and service account only the access required for assigned duties, and treat any elevation beyond that baseline as a privileged grant requiring documented justification and approval, in accordance with the Least Privilege Procedure [DU-2-PRO-717-004].
The Accountable Security Authority must:
- Explicitly authorize which roles may use DroneUp’s security functions and reach security-relevant information, and restrict those privileges to the named roles that demonstrably require them, in accordance with the Least Privilege Procedure [DU-2-PRO-717-004].
- Direct a recurring review of the privileges assigned to each role or class of user to confirm the access still matches a current need, in accordance with the Least Privilege Procedure [DU-2-PRO-717-004].
- Reassign or withdraw any privilege the review finds no longer warranted, in accordance with the Least Privilege Procedure [DU-2-PRO-717-004].
8. Least Privilege for Privileged Accounts
The Accountable Security Authority must:
- Confine privileged accounts to the specific roles entrusted with them, in accordance with the Least Privilege - Privileged Accounts Procedure [DU-2-PRO-717-005].
Individuals holding privileged accounts must:
- Conduct their routine, everyday work from ordinary accounts and call on privileged access only for the tasks that truly require it, in accordance with the Least Privilege - Privileged Accounts Procedure [DU-2-PRO-717-005].
9. Least Privilege for Privileged Functions
Information Systems Personnel must:
- Ensure that only authorized users can carry out privileged actions, and that those actions remain accountable through reliable logging, in accordance with the Least Privilege - Privileged Functions Procedure [DU-2-PRO-717-006].
10. Unsuccessful Logon Attempts
Information Systems Personnel must:
- Ensure that repeated failed sign-in attempts are automatically curtailed so that password guessing and similar attacks cannot continue unchecked, with the specific limits and responses set in the Unsuccessful Logon Attempts Procedure [DU-2-PRO-717-007].
11. System Use Notification
The Accountable Security Authority must:
- Determine the notice users are shown before they sign in, making plain that use is monitored, that access is for authorized purposes only, and that the system may hold Controlled Unclassified Information subject to federal safeguarding, in accordance with the System Use Notification Procedure [DU-2-PRO-717-008].
Information Systems Personnel must:
- Ensure users are presented with that notice and acknowledge it before they are allowed into a system, in accordance with the System Use Notification Procedure [DU-2-PRO-717-008].
12. Device Lock
Information Systems Personnel must:
- Configure DroneUp systems to lock automatically after a defined period of inactivity, and require users to lock their session whenever they leave a system unattended, in accordance with the Device Lock Procedure [DU-2-PRO-717-009].
- Keep the session locked until the user re-establishes access through DroneUp’s identification and authentication process, in accordance with the Device Lock Procedure [DU-2-PRO-717-009].
- Replace on-screen content with a non-revealing image while the device is locked so previously visible information is not exposed, in accordance with the Device Lock Procedure [DU-2-PRO-717-009].
13. Session Termination
Information Systems Personnel must:
- Ensure sessions do not stay open indefinitely and are closed automatically under the conditions set in the Session Termination Procedure [DU-2-PRO-717-010], so that abandoned access cannot later be picked up by someone else.
14. Remote Access
Information Systems Personnel must:
- Define the usage, configuration, and connection requirements governing each permitted method of remote access to DroneUp systems, in accordance with the Remote Access Procedure [DU-2-PRO-717-011].
- Approve each method of remote access before any such connection is established, in accordance with the Remote Access Procedure [DU-2-PRO-717-011].
- Route all remote access into the environment only through entry points DroneUp authorizes and manages, in accordance with the Remote Access Procedure [DU-2-PRO-717-011].
- Treat remote execution of privileged commands and remote access to security-relevant information as an exception permitted only for an authorized, documented need, in accordance with the Remote Access Procedure [DU-2-PRO-717-011].
15. Wireless Access
Information Systems Personnel must:
- Define the usage, configuration, and connection requirements for each type of wireless access permitted to DroneUp systems, in accordance with the Wireless Access Procedure [DU-2-PRO-717-012].
- Approve each type of wireless access before the connection is established, in accordance with the Wireless Access Procedure [DU-2-PRO-717-012].
- Disable wireless capability before a system is issued or deployed wherever wireless use is not intended, in accordance with the Wireless Access Procedure [DU-2-PRO-717-012].
- Protect wireless connections with authentication and encryption so they cannot be joined or intercepted by unauthorized parties, in accordance with the Wireless Access Procedure [DU-2-PRO-717-012].
16. Access Control for Mobile Devices
Information Systems Personnel must:
- Define the usage, configuration, and connection requirements mobile devices must meet to reach DroneUp systems or data, including when operated away from DroneUp premises, in accordance with the Access Control for Mobile Devices Procedure [DU-2-PRO-717-013].
- Authorize each mobile device’s connection to DroneUp systems before access is granted, in accordance with the Access Control for Mobile Devices Procedure [DU-2-PRO-717-013].
- Protect Controlled Unclassified Information on mobile devices through full-device or container-based encryption so it cannot be read if a device is lost or stolen, in accordance with the Access Control for Mobile Devices Procedure [DU-2-PRO-717-013].
17. Use of External Systems
Information Systems Personnel must:
- Prohibit the use of any external or personally owned system to reach DroneUp systems or handle Controlled Unclassified Information unless that system has been specifically authorized, in accordance with the Acceptable Use Policy [DU-1-POL-521-002] and the Use of External Systems Procedure [DU-2-PRO-717-014].
- Establish the security requirements an external system must satisfy before any authorized individual may use it to access DroneUp systems or to process, store, or transmit Controlled Unclassified Information, in accordance with the Use of External Systems Procedure [DU-2-PRO-717-014].
- Permit such use only after confirming the external system meets those requirements and a connection or processing agreement with the hosting entity is in place, in accordance with the Use of External Systems Procedure [DU-2-PRO-717-014].
- Restrict the use of DroneUp-controlled portable storage devices on external systems to expressly permitted cases, in accordance with the Use of External Systems Procedure [DU-2-PRO-717-014].
18. Publicly Accessible Content
The Accountable Security Authority must:
- Limit the ability to post information on public channels to designated individuals, and ensure those individuals are trained to confirm that publicly accessible information contains no Controlled Unclassified Information, in accordance with the Publicly Accessible Content Procedure [DU-2-PRO-717-015].
Authorized publishers must:
- Review content before it is posted to public channels and re-review previously published content, removing any Controlled Unclassified Information or other nonpublic information discovered, in accordance with the Publicly Accessible Content Procedure [DU-2-PRO-717-015].
19. Enforcement and Sanctions
Enforcement and sanctions are handled in accordance with the Information Security Program Policy [DU-1-POL-521-001].
20. Exceptions
Exceptions to this policy are handled in accordance with the Information Security Program Policy [DU-1-POL-521-001].
Document control
| Document number | DU-1-POL-717-001 |
| Title | Access Control Policy |
| Classification | CBI |
| Owner | VP of Operations |
| Approval authority | Accountable Security Authority |
| Exec approval (verified) | John Vernon (CEO) · 2026-06-19 14:32 UTC · PR #1 |
| Effective date | 2026-06-19 |
| Revision | 1 |
| Review cycle | Annual; and upon Significant Change |
| Parent document | DU-1-POL-521-001 |
| Reviewed by | E. Bremer (2026-06-19) |